Description
Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan Rename Author Slug rename-author-slug allows Stored XSS.This issue affects Rename Author Slug: from n/a through <= 1.2.0.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery (CSRF) in the Nazmul Ahsan Rename Author Slug WordPress plugin allows an attacker to submit form data that is stored on the server and later executed as JavaScript when normal site users load the affected page. The vulnerability is specifically a stored XSS that can be triggered by any authenticated user or by tricking an administrator into submitting a malicious request, giving an attacker the ability to steal cookies, session tokens, or perform other client‑side attacks. The weakness stems from the absence of a proper CSRF protection token (CWE‑352).

Affected Systems

The issue affects all releases of the Rename Author Slug plugin up to version 1.2.0. WordPress sites that have installed any of these vulnerable versions are at risk.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score is reported as < 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, an attacker who can successfully perform a CSRF attack could cause stored XSS that is executed in the browsers of any visitor to the site. The attack vector is likely indirect, requiring the attacker to persuade an authenticated user or administrator to submit a specially crafted request, but no additional credentials or system privileges are needed to exploit the flaw.

Generated by OpenCVE AI on May 1, 2026 at 21:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Rename Author Slug plugin to the latest version that includes a CSRF token; the latest patch supersedes all versions up to 1.2.0.
  • If an update is not available or cannot be applied, immediately delete or disable the plugin to eliminate the stored XSS vector.
  • Ensure the underlying WordPress installation is updated to the latest security patch to reduce overall risk.

Generated by OpenCVE AI on May 1, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3304 Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan Rename Author Slug allows Stored XSS.This issue affects Rename Author Slug: from n/a through 1.2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan Rename Author Slug allows Stored XSS.This issue affects Rename Author Slug: from n/a through 1.2.0. Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan Rename Author Slug rename-author-slug allows Stored XSS.This issue affects Rename Author Slug: from n/a through <= 1.2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan Rename Author Slug allows Stored XSS.This issue affects Rename Author Slug: from n/a through 1.2.0.
Title WordPress Rename Author Slug plugin <= 1.2.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:15.264Z

Reserved: 2025-01-16T11:27:31.286Z

Link: CVE-2025-23640

cve-icon Vulnrichment

Updated: 2025-01-17T17:20:46.241Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:41.900

Modified: 2026-06-17T08:56:00.973

Link: CVE-2025-23640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T21:15:25Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)